Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. This has been fixed in 6.4.0.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. This has been fixed in 6.4.0. | |
| Title | Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-27T21:34:39.107Z
Reserved: 2026-02-25T03:11:36.689Z
Link: CVE-2026-27939
No data.
Status : Received
Published: 2026-02-27T22:16:22.993
Modified: 2026-02-27T22:16:22.993
Link: CVE-2026-27939
No data.